77/100 SECURITY SCORE

Certificate Information

Subject
CN=medhawi.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 25, 2025
Valid Until
March 25, 2026 88 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A1:87:3D:0E:7B:A9:3E:BE:76:7B:A2:BE:8C:DB:F1:7D:7E:37:B5:E2:8C:1B:73:0A:2F:A6:0B:0F:4B:88:DE:91
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
dev.sp.pinggo.co.za

Other domains in certificate

aidanish.com
linkstaging.allwayswithyou.com
www.andersonmontana.com
doctor.apna.health
www.applifttechnologies.com
askchefapp.com
www.atacanhayvancilik.com
autoparteslarueda.com
developper.baby-pouss.fr
info.bitlight.kr
admin.biznex.uz
bosols.com
bytheyardenterprise.com
www.camper-connect.de
ai-tutor-workshop-ckt.cloudpssolutions.com
login.clusterfuzz.com
qa.hebot.xbot.com.vn
nceev1.comprendo.dev
coolpic.io
cryptsnaps.com
links.curatedcare.com
dalton.studio
www.dharmagymforall.org.uk
demo.distillhq.com
www.dougmart.in
x2buatrrw9.easyapp.co
emmflowers.com
envistausa.us
eyethuyouth.co.za
fatiskitchen.com
www.fethiyedurakkebap.com
flite.network
s.formito.com
t.gaeyou.com
goseero.com
heyduo.com
link.hmspl.de
homies.llc
hypnotize.nz
collect-coworker-test.digitalse.ikea.com
www.indoorbillboarddisplays.com
intrinsicmastery.co.uk
ironappsdev.com
www.jmfidaho.com
joshdale.net
joshitravels.in
www.julienhouyet.be
www.kalsiumkarbonat.com
www.koeda.fi
letsrocket.dev
lizdresser.com
www.loanpecar.com
www.lukesw.net
www.makorelaboratories.com
marianapparition.net
medhawi.com
www.mergenetu.ro
www.mesbro.com
qas.metryx.app
app.mhub.my
www.mindtechnic.com
yachtingventures.monacofoundry.com
music-tools.net
admin.mutant.one
fund.mynt.in
nyo.ooo
administracion.orsep.cl
paddlingbeyond.de
www.parallel-networks.com
feedback.pitzaslice.com
portalboard.games
prashantmvikram.com
psychopyko.com
quizmarks.com
qwality.space
rear.remodelpartners.net
www.revel.cloud
robotega.com
dev.saptaglobal.com
sechsnimmt.de
www.kundenzone.seekinnovation.at
seudetetivevirtual.net
www.socomontsrl.com
sospapa-moris.com
loft.sphure.app
www.stacygaudreau.com
stuccoplus.co.jp
bodavelasquezchavarria.swanmoments.com
testynadoradcepodatkowego.pl
thehomelucky.com
be-strong.timp.io
torvgarden-tannklinikk.no
app.trainfitpro.com
webgallery.ir
westagsolutions.com
www.whatdidcathiebuy.com
rizoma.xptoconsig.com.br
share-dev.yoou.com
www.zeesne.com